Advertisement
Promo

Security threats Toolkit

VCard security hole leaves Outlook users exposed

Will Knight ZDNet.co.uk

Published: 26 Feb 2001 12:17 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer security experts have issued warnings about a vulnerability affecting Microsoft's Outlook 2000 email client that could allow a hacker to take control of a user's machine.

The vulnerability lies with Outlook's compatibility with vCards (Virtual Cards) -- a special type of file that makes it possible for different email and organiser programs to share contact details.

A malicious computer hacker could create a vCards attachment capable of tricking Outlook or Outlook Express into running any code on a targeted Windows 95, 98, NT or 2000 machine when opened by the recipient. The vulnerability is known as a buffer overflow, because it allows code to execute outside the program's normal perimeters. If the buffer is overrun with random data it causes the application to crash. However, if it is overrun with specially designed code it could allow a third party to take control of a computer system.

Microsoft has issued its own warning concerning the vulnerability and admits that it poses a significant threat to users. The software corporation advises those running Outlook or Outlook Express to apply a specially-created security patch to stop the danger.

Hackers have in the past made use of similar software bugs to create more virulent computer viruses and worms. The Bubbleboy virus and the Kak worm made use of the same vulnerability in Outlook to attack computer systems and spread themselves.

Eric Chien, chief researcher at Symantec's Antivirus Research Centre (SARC) in Europe, said virus writers rarely use buffer overflow exploits. He suggested that a greater risk may be posed by malicious computer hackers looking for a way to target a specific computer network.

"Potentially someone could [use this exploit to] hack a computer," said Chien. "They could drop a Trojan, get inside a firewall and do whatever they want."

Other security experts agreed that the security hole poses a danger to companies and said it highlights the risk of executing unsolicited email attachments.

"Any vulnerability in commonly attached file types exposes corporations to great risk because these problems are often used as the opportunity for the malicious delivery of highly destructive and virulent mail worms," said Royal Hansen, European practice director for security firm @stake. "Again, this is a good example of why corporations must develop security policies that do not trust any attachment from any unknown source even if the type of attachment is considered safe by individual users."

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
39 out of 93 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:

















Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters